
Commonwealth of Kentucky 

STATE BOARD OF ELECTIONS 

Alison Lunoergan Grimes 
Secretary of State & Chief Election OfTtcial 


July 26,2018 

Brian Newby, Executive Director 
U.S. Election Assistance Commission 
1335 East-West Highway, Suite 4300 
Silver Spring, MD 20910 

Dear Mr. Newby, 

As Kentucky's chief elections official and chair of the State Board of Elections, I sincerely appreciate the 
Election Assistance Commission's expeditiousness in issuing the recently appropriated 2018 HAVA 
Election Security Funds, authorized under Title I Section 101 of the Help America Vote Act (HAVA) of 2002. 

Please find enclosed Kentucky's narrative and budget for the more than $5.7 million in HAVA funds 
available to the Commonwealth, which we requested earlier this year. Careful consideration has been given 
to the opportunities this funding provides for increasing election security and election technology as well as 
future implementation of post-election audits. Kentucky will move quickly to utilize this critical funding for 
the maximum benefit of our elections. 

If I may be of any assistance as it relates to the Commonwealth's use of these funds, please do not 
hesitate to contact me. 



Sincerely, 


Alisori Lundergan Grimes 


140 Walnut Street 
Frankfort, KY 40601-3240 



(502) 573-7100 

Fax (502) 573-4369 or (502) 696-1952 
Website; www.elect.ky.gav 


AN EQUAL OPPORTUNITY EMPLOYER M/F/D 







Commonwealth of Kentucky 2018 Help America Vote Act Security Grant Narrative 


The Kentucky State Board of Elections ("SBE"), chaired by Secretary of State Alison Lundergan Grimes, 
submits this narrative as a plan for the 2018 Help America Vote Act ("HAVA") Security Grant. The SBE 
proposes these spending recommendations for the purposes of creating opportunities to increase 
security for election systems, election technology and physical security for election administrators. It is 
further recommended that the SBE use a portion of these funds to begin the process of implementing 
post-election accountability programs, specificaily with the use of risk-limiting audits ("RLAs"). 

The SBE will continue to work with our security partners -The Office of the Secretary of State, the 
Commonwealth of Kentucky HAVA Advisory Board, the United States Department of Homeland Security, 
and local election officials - throughout the upcoming flscal cycles to ensure the appropriate allocation 
and use of funds as the grant is drawn down. Further, the Commonwealth of Kentucky will comply with 
all matching commitments and obligations. The following expenditures account for a $5,773,423 budget. 


Project Categories 

FY2018 

FY2019 

Total 

Voting Equipment Replacement & Upgrades 

$2,300,000 

$2,300,000 

$4,600,000 

Election Auditing 

$50,000 



Cybersecurity Personnel: 




CISC. 

$125,000 

$125,000 

$250,000 

Systems Architect. 

$123,423 


$123,423 

Physical Security 

See Total 

See Total 

$250,000 

Security Software Solutions 

$150,000 

$150,000 

$300,000 

Training 

$50,000 

$50,000 

$100,000 

Total: 

$2,798,423 

$2,725,000 

5,773,423 


Voter Verified Paper Audit Trail and Training: 

The Commonwealth of Kentucky does not exclusively utilize voting machines which create a Voter 
Verified Paper Audit Trail ("WPAT") at the point of the voter casting his or her ballot. Approximately 
twenty-nine of Kentucky's one hundred and twen^ counties utilize what are commonly referred to as 
direct-recording electronic voting machines ("DRE's") for all ballot submissions, while the majority of 
Kentucky counties rely on DRE's only for voting machines designated as voter accessibility compliant 
machines. These two categories of usage represent approximately 13,000 voting machines. To replace 
these machines completely will cost approximately $18,000,000 - $28,000,000 depending on the vendor 
and type of solution. 



































Commonwealth of Kentucky 2018 Help America Vote Act Security Grant Narrative 


The SBE recently resolved to require all future purchases of voting equipment in the Commonwealth of 
Kentucky to provide a WPAT. This resolution requires counties to begin planning for the replacement of 
DRE machines. The SBE recommends that a majority of the federal funding be utiiized in this 
replacement endeavor and training on election equipment and communications. While it will not 
account for the complete statewide replacement purchase price, it will assist the counties who solely 
use DRE's to make this transition immediately. Once the Commonwealth of Kentucky has adopted a 
statewide WPAT system we will then have the ability to begin risk-limiting audits as a standard post¬ 
election accountability protocol. 

Critical Infrastructure Security: 

Cyber Security Personnel / Cyber Security Systems 
Chief Information Security Officer (CISO) 

A portion of the 2018 HAVA funding will be used to hire a full-time SBE Chief Information Security 
Officer ("CISO"), who will work exclusively on matters related to elections cyber security. The CISO's 
responsibilities wiil include the coordination of all SBE cyber security and cyber hygiene efforts. These 
efforts will include, but may not be limited to, securing the Commonwealth's Voter Registration 
Database ("VRS"), internal office software and hardware, election software and hardware, and the 
training of and service to all 120 county clerks and county boards of elections. 

Security Architecture Consultant 

Overthe next two fiscal years, the SBE will develop and produce an updated version of the 
Commonwealth's Voter Registration System with additional cybersecurity tools built into the 
architecture. To this end, SBE intends to hire a full-time systems architect who is proficient in 
fundamental database languages as well as having a strong background in systems and security 
architecture. 

Physical Security 

A portion of funding will be used in the Commonwealth of Kentucky's efforts to identify and rectify all 
physical security needs and concerns specific to the SBE physical location. While the SBE servers are 
housed within a secure hardened state-owned facility it is of equal importance that the physical SBE 
property and systems are secured to a level appropriate for critical infrastructure. SBE facilities should 
ultimately meet the United States Department of Homeland Security ("DHS") physical security standards 
and protocols. The SBE is collaborating with the DHS to identify deficiencies in our current facility and is 
working to implement proposed solutions. 

Post-Election Accountability: 

Risk Limiting Audits (RLA) Research and Implementation 

A portion of the HAVA funding will be used to research national best practices and standards for Risk 
Limiting Audits with the goal of statewide implementation once the Commonwealth of Kentucky is fully 
WPAT compliant. 




